Libpng Library Remote Denial of Service Vulnerability
BID:24000
Info
Libpng Library Remote Denial of Service Vulnerability
| Bugtraq ID: | 24000 |
| Class: | Design Error |
| CVE: |
CVE-2007-2445 |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2007 12:00AM |
| Updated: | Mar 23 2009 03:56PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Ubuntu Ubuntu Linux 7.04 sparc Ubuntu Ubuntu Linux 7.04 powerpc Ubuntu Ubuntu Linux 7.04 i386 Ubuntu Ubuntu Linux 7.04 amd64 Ubuntu Ubuntu Linux 6.10 sparc Ubuntu Ubuntu Linux 6.10 powerpc Ubuntu Ubuntu Linux 6.10 i386 Ubuntu Ubuntu Linux 6.10 amd64 Ubuntu Ubuntu Linux 6.06 LTS sparc Ubuntu Ubuntu Linux 6.06 LTS powerpc Ubuntu Ubuntu Linux 6.06 LTS i386 Ubuntu Ubuntu Linux 6.06 LTS amd64 Turbolinux Turbolinux Server 10.0 x86 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 10.0.0 x64 Turbolinux Turbolinux Desktop 10.0 Turbolinux Turbolinux FUJI Turbolinux Turbolinux 10 F... TurboLinux Personal TurboLinux Multimedia Turbolinux Home Turbolinux FUJI 0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Turbolinux Appliance Server 1.0 Workgroup Edition Turbolinux Appliance Server 1.0 Hosting Edition Turbolinux Appliance Server 2.0 TransSoft Broker FTP Server 8.0 Sun Solaris 9_x86 Sun Solaris 9 Sun Solaris 8_x86 Sun Solaris 8_sparc Sun Solaris 10_x86 Sun Solaris 10 SGI ProPack 3.0 SP6 rPath rPath Linux 1 Redhat Fedora Core6 Redhat Fedora Core5 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux WS 2.1 IA64 Redhat Enterprise Linux WS 2.1 Redhat Enterprise Linux Virtualization 5 Server Redhat Enterprise Linux Supplementary 5 server Redhat Enterprise Linux Optional Productivity Application 5 server Redhat Enterprise Linux Hardware Certification 5 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux ES 2.1 IA64 Redhat Enterprise Linux ES 2.1 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop Supplementary 5 client Redhat Enterprise Linux Desktop Multi OS 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux Clustering 5 server Redhat Enterprise Linux Cluster-Storage 5 server Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Enterprise Linux AS 2.1 IA64 Redhat Enterprise Linux AS 2.1 Redhat Enterprise Linux Desktop version 4 Redhat Enterprise Linux 5 Server Redhat Desktop 4.0 Redhat Desktop 3.0 Redhat Advanced Workstation for the Itanium Processor 2.1 IA64 Redhat Advanced Workstation for the Itanium Processor 2.1 OpenPKG OpenPKG E1.0-Solid OpenPKG OpenPKG Current Mandriva Linux Mandrake 2007.1 x86_64 Mandriva Linux Mandrake 2007.1 Mandriva Linux Mandrake 2007.0 x86_64 Mandriva Linux Mandrake 2007.0 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Linux Terminal Server Project Linux Terminal Server Project 4.2 libpng libpng3 1.2.12 libpng libpng3 1.2.11 libpng libpng3 1.2.10 libpng libpng3 1.2.8 libpng libpng3 1.2.7 libpng libpng3 1.2.5 libpng libpng3 1.2.1 libpng libpng3 1.2 .0 libpng libpng 1.0.18 libpng libpng 1.0.17 libpng libpng 1.0.16 libpng libpng 1.0.15 libpng libpng 1.0.14 libpng libpng 1.0.13 libpng libpng 1.0.12 libpng libpng 1.0.11 libpng libpng 1.0.10 libpng libpng 1.0.9 libpng libpng 1.0.8 libpng libpng 1.0.7 libpng libpng 1.0.6 libpng libpng 1.0.5 libpng libpng 1.0 libpng libpng 0.90 Irrlicht Engine Irrlicht Engine 1.3 Irrlicht Engine Irrlicht Engine 1.2 Irrlicht Engine Irrlicht Engine 1.1 Google Android Software Development Kit (SDK) m3-rc37a Gentoo Linux Foresight Linux Foresight Linux 1.1 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Debian Linux 4.0 sparc Debian Linux 4.0 s/390 Debian Linux 4.0 powerpc Debian Linux 4.0 mipsel Debian Linux 4.0 mips Debian Linux 4.0 m68k Debian Linux 4.0 ia-64 Debian Linux 4.0 ia-32 Debian Linux 4.0 hppa Debian Linux 4.0 armel Debian Linux 4.0 arm Debian Linux 4.0 amd64 Debian Linux 4.0 alpha Debian Linux 4.0 Avaya SES 3.1.1 Avaya SES 3.0 Avaya SES 2.0 Avaya Messaging Storage Server MSS 3.0 Avaya Messaging Storage Server MM3.0 Avaya Messaging Storage Server 2.0 Avaya Messaging Storage Server 1.0 Avaya Messaging Storage Server Avaya Message Networking MN 3.1 Avaya Message Networking Avaya Communication Manager 2.0.1 Avaya Communication Manager 2.0 Avaya CCS 3.1.1 Avaya CCS 3.0 Avaya CCS 2.0 Avaya Aura Application Enablement Services 3.1.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X 10.5.2 |
| Not Vulnerable: |
Linux Terminal Server Project Linux Terminal Server Project 5.0 libpng libpng 1.2.17 libpng libpng 1.0.25 Irrlicht Engine Irrlicht Engine 1.3.1 Google Android Software Development Kit (SDK) m5-rc15 |
Discussion
Libpng Library Remote Denial of Service Vulnerability
The 'libpng' library is prone to a remote denial-of-service vulnerability because the library fails to handle malicious PNG files.
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected library.
This issue affects 'libpng' 1.2.16 and prior versions.
The 'libpng' library is prone to a remote denial-of-service vulnerability because the library fails to handle malicious PNG files.
Successful exploits may allow remote attackers to cause denial-of-service conditions on computers running the affected library.
This issue affects 'libpng' 1.2.16 and prior versions.
Exploit / POC
Libpng Library Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Libpng Library Remote Denial of Service Vulnerability
Solution:
Vendor advisories are available. Please see the references for details.
Debian Linux 5.0 alpha
Sun Solaris 10
Debian Linux 4.0 amd64
Debian Linux 4.0 ia-32
Irrlicht Engine Irrlicht Engine 1.3
Debian Linux 5.0 armel
Debian Linux 5.0 mips
Debian Linux 4.0 mips
Debian Linux 5.0 sparc
Debian Linux 4.0 arm
Debian Linux 4.0 powerpc
Debian Linux 4.0 m68k
Debian Linux 5.0 s/390
Irrlicht Engine Irrlicht Engine 1.2
Irrlicht Engine Irrlicht Engine 1.1
Debian Linux 5.0 hppa
Debian Linux 4.0 sparc
Debian Linux 5.0 m68k
Debian Linux 5.0 ia-64
Debian Linux 5.0 mipsel
libpng libpng 1.0.10
libpng libpng 1.0.16
libpng libpng 1.0.17
Apple Mac OS X 10.5.2
Apple Mac OS X Server 10.5.2
Solution:
Vendor advisories are available. Please see the references for details.
Debian Linux 5.0 alpha
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_alpha.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_alpha.udeb -
Debian libpng12-0_1.2.27-2+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_alpha.deb -
Debian libpng12-dev_1.2.27-2+lenny2_alpha.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_alpha.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Sun Solaris 10
Debian Linux 4.0 amd64
-
Debian libpng12-0-udeb_1.2.15~beta5-1+etch2_amd64.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.15~beta5-1+etch2_amd64.udeb -
Debian libpng12-0_1.2.15~beta5-1+etch2_amd64.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.15~beta5-1+etch2_amd64.deb -
Debian libpng12-dev_1.2.15~beta5-1+etch2_amd64.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.15~beta5-1+etch2_amd64.deb -
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Debian Linux 4.0 ia-32
-
Debian libpng12-0-udeb_1.2.15~beta5-1+etch2_i386.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.15~beta5-1+etch2_i386.udeb -
Debian libpng12-0_1.2.15~beta5-1+etch2_i386.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.15~beta5-1+etch2_i386.deb -
Debian libpng12-dev_1.2.15~beta5-1+etch2_i386.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.15~beta5-1+etch2_i386.deb -
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Irrlicht Engine Irrlicht Engine 1.3
-
Irrlicht Engine irrlicht-1.3.1.zip
http://prdownloads.sourceforge.net/irrlicht/irrlicht-1.3.1.zip?downloa d
Debian Linux 5.0 armel
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_armel.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_armel.udeb -
Debian libpng12-0_1.2.27-2+lenny2_armel.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_armel.deb -
Debian libpng12-dev_1.2.27-2+lenny2_armel.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_armel.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Debian Linux 5.0 mips
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_mips.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_mips.udeb -
Debian libpng12-0_1.2.27-2+lenny2_mips.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_mips.deb -
Debian libpng12-dev_1.2.27-2+lenny2_mips.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_mips.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Debian Linux 4.0 mips
-
Debian libpng12-0-udeb_1.2.15~beta5-1+etch2_mips.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.15~beta5-1+etch2_mips.udeb -
Debian libpng12-0_1.2.15~beta5-1+etch2_mips.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.15~beta5-1+etch2_mips.deb -
Debian libpng12-dev_1.2.15~beta5-1+etch2_mips.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.15~beta5-1+etch2_mips.deb -
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Debian Linux 5.0 sparc
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_sparc.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_sparc.udeb -
Debian libpng12-0_1.2.27-2+lenny2_sparc.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_sparc.deb -
Debian libpng12-dev_1.2.27-2+lenny2_sparc.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_sparc.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Debian Linux 4.0 arm
-
Debian libpng12-0-udeb_1.2.15~beta5-1+etch2_arm.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.15~beta5-1+etch2_arm.udeb -
Debian libpng12-0_1.2.15~beta5-1+etch2_arm.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.15~beta5-1+etch2_arm.deb -
Debian libpng12-dev_1.2.15~beta5-1+etch2_arm.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.15~beta5-1+etch2_arm.deb -
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Debian Linux 4.0 powerpc
-
Debian libpng12-0-udeb_1.2.15~beta5-1+etch2_powerpc.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.15~beta5-1+etch2_powerpc.udeb -
Debian libpng12-0_1.2.15~beta5-1+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.15~beta5-1+etch2_powerpc.deb -
Debian libpng12-dev_1.2.15~beta5-1+etch2_powerpc.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.15~beta5-1+etch2_powerpc.deb -
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Debian Linux 4.0 m68k
-
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Debian Linux 5.0 s/390
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_s390.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_s390.udeb -
Debian libpng12-0_1.2.27-2+lenny2_s390.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_s390.deb -
Debian libpng12-dev_1.2.27-2+lenny2_s390.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_s390.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Irrlicht Engine Irrlicht Engine 1.2
-
Irrlicht Engine irrlicht-1.3.1.zip
http://prdownloads.sourceforge.net/irrlicht/irrlicht-1.3.1.zip?downloa d
Irrlicht Engine Irrlicht Engine 1.1
-
Irrlicht Engine irrlicht-1.3.1.zip
http://prdownloads.sourceforge.net/irrlicht/irrlicht-1.3.1.zip?downloa d
Debian Linux 5.0 hppa
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_hppa.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_hppa.udeb -
Debian libpng12-0_1.2.27-2+lenny2_hppa.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_hppa.deb -
Debian libpng12-dev_1.2.27-2+lenny2_hppa.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_hppa.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Debian Linux 4.0 sparc
-
Debian libpng12-0-udeb_1.2.15~beta5-1+etch2_sparc.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.15~beta5-1+etch2_sparc.udeb -
Debian libpng12-0_1.2.15~beta5-1+etch2_sparc.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.15~beta5-1+etch2_sparc.deb -
Debian libpng12-dev_1.2.15~beta5-1+etch2_sparc.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.15~beta5-1+etch2_sparc.deb -
Debian libpng3_1.2.15~beta5-1+etch2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.1 5~beta5-1+etch2_all.deb
Debian Linux 5.0 m68k
-
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Debian Linux 5.0 ia-64
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_ia64.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_ia64.udeb -
Debian libpng12-0_1.2.27-2+lenny2_ia64.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_ia64.deb -
Debian libpng12-dev_1.2.27-2+lenny2_ia64.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_ia64.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
Debian Linux 5.0 mipsel
-
Debian libpng12-0-udeb_1.2.27-2+lenny2_mipsel.udeb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0-ud eb_1.2.27-2+lenny2_mipsel.udeb -
Debian libpng12-0_1.2.27-2+lenny2_mipsel.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-0_1. 2.27-2+lenny2_mipsel.deb -
Debian libpng12-dev_1.2.27-2+lenny2_mipsel.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng12-dev_ 1.2.27-2+lenny2_mipsel.deb -
Debian libpng3_1.2.27-2+lenny2_all.deb
http://security.debian.org/pool/updates/main/libp/libpng/libpng3_1.2.2 7-2+lenny2_all.deb
libpng libpng 1.0.10
-
libpng libpng-1.2.18.tar.gz
http://prdownloads.sourceforge.net/libpng/libpng-1.2.18.tar.gz
libpng libpng 1.0.16
-
libpng libpng-1.2.18.tar.gz
http://prdownloads.sourceforge.net/libpng/libpng-1.2.18.tar.gz
libpng libpng 1.0.17
-
libpng libpng-1.2.18.tar.gz
http://prdownloads.sourceforge.net/libpng/libpng-1.2.18.tar.gz
Apple Mac OS X 10.5.2
-
Apple SecUpd2008-002.dmg
http://wsidecar.apple.com/cgi-bin/nph-reg3rdpty2.pl/product=18157&cat= 57&platform=osx&method=sa/SecUpd2008-002.dmg
Apple Mac OS X Server 10.5.2
References
Libpng Library Remote Denial of Service Vulnerability
References:
References:
- Irrlicht Engine Home Page (Irrlicht Engine)
- libpng Homepage (libpng)
- Libpng-1.2.16-ADVISORY.txt (PNG Development Group)
- [ GLSA 200805-07 ] Linux Terminal Server Project: Multiple vulnerabilities (Robert Buchholz
) - ASA-2007-254 libpng security update (RHSA-2007-0356) (Avaya)
- Red Hat Security Advisory RHSA-2007-0356: libpng security update (Red Hat )
- Solution 200871: libpng(3) Contains a Denial of Service (DoS) Vulnerability (Sun Microsystems)
- Sun Alert ID 102987 - libpng(3) Contains a Denial of Service (DoS) Vulnerability (Sun Microsystems)
- Vulnerability Note VU#684664 (US-CERT)